HIGH8.8
GHSA-8wj3-cpmr-8whp
Cockpit Content Platform vulnerable to 2FA bypass
Quick fix
GHSA-8wj3-cpmr-8whp — cockpit-hq/cockpit: upgrade to the fixed version with the command below.
composer require cockpit-hq/cockpit:^2.2.2Details
Cockpit Content Platform through version 2.2.1 is vulnerable to a two-factor authentication (2FA) bypass. The 2FA secret is disclosed in a JWT token after user logs into their account, allowing an attacker to bypass the 2FA code. A patch is available on the `develop` branch and is expected to be part of version 2.2.2.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/cockpit-hq/cockpit
Introduced in:
0Fixed in: 2.2.2Fix
composer require cockpit-hq/cockpit:^2.2.2